
WhatWeb
Next generation web scanner

Next generation web scanner

Automated Security Testing For REST API's

Twitter vulnerable snippets

AzureGoat : A Damn Vulnerable Azure Infrastructure

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

GCPGoat : A Damn Vulnerable GCP Infrastructure

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

CVE-2026-9830 Proof of Concept

WEB SERVICE SECURITY ASSESSMENT TOOL

BoB Web Application Security Project

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Performing automated scan using Burp Suite Pro & Vmware Burp Rest API

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

RESTful API wrapping Nmap for automated network scanning, port detection, service enumeration, and vulnerability analysis with optional AI-powered…

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

CVE-2024-28955 Exploitation PoC

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information